New — Iris AI drafts your firewall, routing & rate-limit rules. Explore AI features →
Back to Blog
networkingproduct

Static Egress IPs Explained

A partner says “send us your IP and we'll allowlist it.” Behind a shared edge, that IP isn't stable. A static egress IP makes your outbound traffic come from one address you can hand over with confidence.

3 min read

Plenty of integrations gate access by source IP. A bank's API, a partner's firewall, an on-prem database behind a corporate perimeter — they all want a fixed address to put on an allowlist. The problem: when your traffic leaves through a shared, multi-tenant edge, the outbound IP isn't yours alone and isn't guaranteed to stay the same. A static egress IP fixes that.

The allowlist problem

"Outbound" here means traffic Ngris sends to your backends and partner systems on your behalf. If that traffic can come from any IP in a shared pool, the only safe allowlist a partner can write is a broad one — which defeats the point. You want a single, predictable address so the partner can allow exactly that and nothing else.

What a static egress IP is

A static egress IP gives your endpoints consistent outbound routing through a fixed address. You hand that one IP to the partner or drop it into the firewall rule, and it doesn't drift. Configure it from Endpoint Settings → Egress in the dashboard, or via the API.

It comes in two forms:

  • Dedicated egress IP — an address reserved for you, starting at $10/month.
  • Shared egress IP — available on Pro plans and above, when a stable-but-shared address is enough.

Static egress IPs are an add-on available on all paid plans. Full details are in the Static Egress IP docs.

Egress is not the same as a dedicated ingress IP

This is the part that trips people up, so it's worth being precise. Egress and ingress are opposite directions:

Static egress IP (outbound)

The address your traffic leaves from. Use it so a partner or firewall can allowlist a single source IP for the requests Ngris makes on your behalf.

Dedicated IP (inbound)

A stable, exclusive address your endpoint is reached at. Published as a plain DNS A record (single region) or a CNAME to a per-region GeoDNS group. Useful when an upstream needs to allowlist where it connects to.

If you need a fixed inbound address, that's the dedicated ingress IP: $10/month per IP plus a one-time setup fee, with an account cap of 6 IPs total, and a choice of a single-region A record or a per-region GeoDNS group. It's a different add-on from egress — see the Dedicated IPs docs. Reach for static egress when the requirement is "your traffic must come from this IP," and a dedicated ingress IP when it's "we must connect to this IP."

When you'd reach for static egress

  • Partner APIs that allowlist callers by source IP.
  • Corporate firewalls in front of an on-prem service you're integrating with.
  • Databases and internal systems reachable only from approved addresses.

Compare add-on options on the pricing page, or talk to us about volume and dedicated provisioning on the enterprise page.

Give partners one IP to allowlist

Add a static egress IP to your endpoints for consistent outbound routing.

Create a free account →
Ask an AI to summarise this page
Product
API Gateway Secure Tunnels WAF & Firewall Traffic Inspector
AI
Iris AI AI Gateway
More
Solutions Developers Pricing Enterprise Sign in Get Started Free
Iris